Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.18.2.2024.2585.1
Categoría:openSUSE Local Security Checks
Título:openSUSE Security Advisory (SUSE-SU-2024:2585-1)
Resumen:The remote host is missing an update for the 'kernel-firmware-nvidia-gspx-G06' package(s) announced via the SUSE-SU-2024:2585-1 advisory.
Descripción:Summary:
The remote host is missing an update for the 'kernel-firmware-nvidia-gspx-G06' package(s) announced via the SUSE-SU-2024:2585-1 advisory.

Vulnerability Insight:
This update for kernel-firmware-nvidia-gspx-G06 fixes the following issues:

Update to version 555.42.06 for CUDA.

Security Update 550.90.07:

- CVE-2024-0090: Fixed out of bounds write (bsc#1223356).
- CVE-2024-0092: Fixed incorrect exception handling (bsc#1223356).
- CVE-2024-0091: Fixed untrusted pointer dereference (bsc#1223356).

Changes in kernel-firmware-nvidia-gspx-G06:

- Update to 550.100 (bsc#1227575)

- Add a second flavor to be used by the kernel module versions
used by CUDA. The firmware targetting CUDA contains '-cuda' in
its name to track its versions separately from the graphics
firmware. (bsc#1227417)

Changes in nvidia-open-driver-G06-signed:

- Update to 550.100 (bsc#1227575)

* Fixed a bug that caused OpenGL triple buffering to behave like
double buffering.

- To avoid issues with missing dependencies when no CUDA repo
is present make the dependecy to nvidia-compute-G06 conditional.

- CUDA is not available for Tumbleweed, exclude the build of the
cuda flavor.

- preamble: let the -cuda flavor KMP require the -cuda flavor
firmware

- Add a second flavor for building the kernel module versions
used by CUDA. The kmp targetting CUDA contains '-cuda' in
its name to track its versions separately from the graphics
kmp. (bsc#1227417)
- Provide the meta package nv-prefer-signed-open-driver to
make sure the latest available SUSE-build open driver is
installed - independent of the latest available open driver
version in he CUDA repository.
Rationale:
The package cuda-runtime provides the link between CUDA and
the kernel driver version through a
Requires: cuda-drivers >= %version
This implies that a CUDA version will run withany kernel driver
version equal or higher than a base version.
nvidia-compute-G06 provides the glue layer between CUDA and
a specific version of he kernel driver both by providing
a set of base libraries and by requiring a specific kernel
version. 'cuda-drivers' (provided by nvidia-compute-utils-G06)
requires an unversioned nvidia-compute-G06. With this, the
resolver will install the latest available and applicable
nvidia-compute-G06.
nv-prefer-signed-open-driver then represents the latest available
open driver version and restricts the nvidia-compute-G06 version
to it. (bsc#1227419)

Affected Software/OS:
'kernel-firmware-nvidia-gspx-G06' package(s) on openSUSE Leap 15.6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:L/AC:L/Au:S/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2024-0090
https://nvidia.custhelp.com/app/answers/detail/a_id/5551
Common Vulnerability Exposure (CVE) ID: CVE-2024-0091
Common Vulnerability Exposure (CVE) ID: CVE-2024-0092
CopyrightCopyright (C) 2025 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.